Business Heads

Legal

Privacy Policy

Business Heads Pty Ltd (ABN 78 693 566 326) · Version 1.0 · Effective 1 July 2026

1.  ABOUT THIS POLICY

Business Heads Pty Ltd (we, us, our) is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains what personal information we collect, how we use and disclose it, and how you can access, correct, update or request deletion of your information.

Personal information means information or an opinion about an identified individual or a reasonably identifiable individual, whether true or not, in accordance with the Privacy Act 1988 (Cth).

This policy is consistent with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Spam Act 2003 (Cth). It applies to all personal information we collect in connection with the Business Heads platform, membership, events and quarterly prize draw.

By using our website, signing up for a membership, registering for an event or entering our prize draw, you agree to the collection and use of your information as described in this policy.

2.  WHO THIS POLICY APPLIES TO

This policy applies to current and prospective Business Heads members, event attendees whether or not they are members, quarterly prize draw entrants, and visitors to www.businessheads.com.au.

The Business Heads platform is for individuals aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, contact us at hello@businessheads.com.au and we will delete it promptly.

3.  WHAT INFORMATION WE COLLECT

We collect different types of personal information depending on how you interact with us.

CategoryExamplesPrimary purposeRetention
Member profileFirst name, last name, business name, job title, LinkedIn URL, profile photo, bio, industry, locationMember directory, platform access, community participationDeleted within 30 days of membership ending
Contact detailsEmail address, phone number (if provided)Membership admin, communications, direct marketing with consentUp to 2 years after membership ends, then deleted or de-identified
Payment and billingBilling address, ABN, transaction records. Card numbers processed by Stripe — not held by Business Heads.Processing payments, financial records7 years (ATO)
Event registrationName, contact details, dietary or accessibility requirements (if provided), ticket recordsEvent administration and attendance2 years from event
Competition entriesName, contact details, membership status, qualifying transaction recordsAdministering the draw, verifying eligibility, notifying winners7 years (members)
LinkedIn dataName, photo, job title and employer, where you choose to link your LinkedIn profilePre-populating member profile, member directoryTreated as member profile data
Website analyticsIP address, browser type, device type, pages visited, session durationUnderstanding site usage, improving the platform26 months
CommunicationsEmails, enquiries and support messages sent to usResponding to enquiries, improving our service, legal records3 years from last interaction

1.  Sensitive information

We do not intentionally collect sensitive information as defined in the Privacy Act. If you provide dietary or accessibility requirements when registering for an event, we treat this as sensitive information, collect it only with your consent, and use it solely to manage your attendance at that event.

2.  Information we do not collect

We do not collect government identifiers such as tax file numbers, passport numbers or Medicare numbers.

4.  HOW WE COLLECT YOUR INFORMATION

1.  Collecting personal information

We collect personal information directly from you when you sign up for a membership, create or update your member profile, purchase event tickets, enter the quarterly prize draw, contact us, or visit our website. We do not collect personal information from third parties without your knowledge, except as described below.

2.  LinkedIn and third-party sign-in

If you choose to link your LinkedIn profile to your Business Heads profile, we collect the information you make available through that connection, including your name, profile photo, job title and employer. This is optional. LinkedIn-sourced data is treated as member profile data and handled in accordance with this policy. You can disconnect LinkedIn at any time through the member platform.

5.  HOW WE USE YOUR INFORMATION

1.  The purpose for which it was collected

We use your personal information to:

  • manage your membership and provide access to member benefits;
  • display your profile in the member directory to other current members;
  • process payments and maintain financial records;
  • administer the quarterly prize draw and notify winners;
  • manage event registrations and attendance;
  • send you membership communications, renewal reminders and receipts;
  • send you marketing communications about Business Heads where you have consented or where it is within reasonable expectations given your membership;
  • respond to your enquiries and provide support;
  • improve the website and member platform; and
  • comply with our legal obligations.

We will not use your personal information for any purpose incompatible with the purpose for which it was collected, unless you consent or an exception under the Privacy Act applies.

2.  Aggregated data

We may use de-identified, aggregated data about our membership for internal analysis and reporting. Aggregated data does not identify individual members and is not sold or shared with third parties in a form that could identify you.

6.  SHARING YOUR INFORMATION

1.  General principle

We do not sell your personal information to third parties. We share your information only in the circumstances described in this section.

2.  Member directory

Your member profile is visible to other current Business Heads members through the member directory. See section 10 for details of what information is included and how you can manage your profile.

3.  Rewards Gateway

When you become a member, we share your first name, last name and email address with Rewards Gateway to create your access to the Business Heads member deals program. Once your account is created, Rewards Gateway processes your personal information, including your activity on the deals platform, under its own Privacy Policy. Business Heads notifies Rewards Gateway when your membership ends, at which point Rewards Gateway retains your data for 60 days before deletion, with order history retained for 2 years.

We encourage you to read Rewards Gateway’s Privacy Policy before using the deals platform.

4.  Member deals and referrals

If you express interest in a deal or offer made available by another member business (separate from the Rewards Gateway program), we may share your name and contact details with that member business to facilitate the connection, or you can make the connection yourself. We will notify you before any such sharing occurs. Once shared, that member business’s own privacy practices govern how they handle your information.

5.  Competition administration

Personal information collected from prize draw entrants is used to administer the draw, verify eligibility and notify winners. Winner names and general location may be published in accordance with the Competition Rules. We do not use prize draw entry data for marketing purposes without your consent.

6.  Events

We may share attendee information with third-party event suppliers, including venue operators, to manage event attendance and logistics. Photographers or videographers may be present at Business Heads events and we will notify attendees in advance where images may be taken and used in our communications. Where a Business Heads event involves a co-host, sponsor or event partner, any sharing of attendee information with that partner will be disclosed at the time of event registration.

7.  Service providers

We share personal information with third-party service providers who assist us in operating the platform and delivering services. These providers are permitted to use your information only for the specific purpose for which it was shared. Current providers are listed in section 8.

8.  Legal requirements

We may disclose your personal information where required or authorised by law, including to comply with a court order, subpoena or regulatory requirement, or to protect the rights, property or safety of Business Heads, our members or others.

9.  Business sale or transfer

If Business Heads is sold, merged or transferred to another entity, your personal information may be transferred as part of that transaction. We will notify you before any such transfer and ensure the receiving entity is bound by privacy obligations consistent with this policy. If we cease to operate, member profile data will be deleted within 30 days of platform closure.

7.  DIRECT MARKETING AND THE SPAM ACT

We may use your contact details to send you information about Business Heads membership, events, prize draws and community news, where you have consented or where it is within reasonable expectations given your membership. Entering our quarterly prize draw does not constitute consent to receive marketing communications.

All commercial electronic messages we send comply with the Spam Act 2003 (Cth). This means:

  • for members, we may rely on inferred consent arising from your active membership relationship with us;
  • for all other individuals, we will only send marketing communications where you have given express consent;
  • every marketing email we send identifies Business Heads as the sender and includes our contact details; and
  • every marketing email includes a clear and functional unsubscribe mechanism.

You can opt out of direct marketing at any time by using the unsubscribe link in any email we send, or by contacting us at hello@businessheads.com.au. We will process opt-out requests within 5 business days. Opting out does not affect transactional communications about your membership, such as renewal reminders, receipts and account notices.

8.  OVERSEAS DISCLOSURE AND THIRD-PARTY PROVIDERS

We use third-party service providers and platforms to operate Business Heads. Some process data outside Australia. We take reasonable steps to ensure all providers handle personal information consistently with the Australian Privacy Principles, including by accepting their data processing agreements.

1.  Third-party platforms you interact with directly

Business Heads provides access to two third-party platforms that you will use directly as a member:

Circle (community platform): The Business Heads online community is hosted on Circle’s platform. Your posts, messages, profile activity and interactions within the community are processed by Circle under Circle’s Terms of Service and Privacy Policy. Circle processes this data independently of Business Heads. Business Heads has entered into Circle’s Data Processing Agreement to govern the handling of member personal information. We encourage you to read Circle’s privacy policy at circle.so/privacy.

Rewards Gateway (member deals): Your access to and use of the Business Heads member deals program is provided through Rewards Gateway’s platform. Rewards Gateway processes your data under its own Privacy Policy. See section 6 for details of what information Business Heads shares with Rewards Gateway to create your account.

Business Heads is not responsible for the privacy practices of Circle or Rewards Gateway beyond the obligations set out in our data processing agreements with each provider.

ProviderCountryPurpose
StripeUnited StatesProcessing membership and event payments. Card data held by Stripe, not Business Heads. See stripe.com/au/privacy.
CircleUnited StatesMember community platform. Hosts the Business Heads online community and member directory. Members interact directly with Circle's platform. DPA in place. See circle.so/privacy.
Rewards GatewayUnited Kingdom / AustraliaMember deals and rewards program. Business Heads shares first name, last name and email to create member accounts. See rewardsgateway.com.au for their privacy policy.
Email HubUnited StatesSending membership communications, newsletters and event notifications.
Google AnalyticsUnited StatesWebsite analytics, usage data and performance monitoring.
VercelUnited StatesHosting the Business Heads website.
SupabaseUnited StatesLead enquiries submitted through this website are stored using Supabase, a database service provided by Supabase Inc.

We will update this table when we add or change providers.

9.  COOKIES AND WEBSITE ANALYTICS

Our website uses cookies and similar technologies to support platform functionality and to understand how the site is used.

Cookie typePurposeCan you opt out?
Essential cookiesKeeping you logged in, maintaining your session, securityNo. The platform cannot function without these.
Analytics cookiesUnderstanding site usage and improving the platformYes. Via your browser settings or Google’s opt-out browser add-on.

By continuing to use our website, you consent to our use of cookies as described above. Most browsers allow you to manage or disable cookies through their settings. Disabling essential cookies may affect your ability to use the member platform.

10.  MEMBER DIRECTORY AND PROFILE PRIVACY

1.  What is visible and to whom

Your member profile is visible to other current Business Heads members only through the Business Heads community on Circle’s platform. It is not visible to the general public, to former members or to individuals who are not logged in.

2.  Mandatory and optional fields

The following fields are required to create a member profile: first name, last name and business name. All other profile fields, including job title, LinkedIn URL, profile photo, bio, industry and location, are optional. You choose what you share.

3.  Managing your profile

You can update, restrict or remove information from your member profile at any time through the member platform, without needing to cancel your membership. If you need assistance, contact us at hello@businessheads.com.au and we will respond within 5 business days.

4.  Responsible use of directory information

By accessing the member directory, you agree to use the information you find there only for genuine professional networking purposes. You must not use directory information to send unsolicited commercial messages to other members, copy or harvest the directory for use outside the platform, or share other members’ information with third parties without their consent. Breach of these obligations may result in suspension or cancellation of your membership. Business Heads is not liable for misuse of directory information by other members but will investigate and act on complaints.

5.  Profile removal on membership ending

Your profile will be removed from the member directory within 30 days of your membership ending. Contact details and transaction records will be retained for the periods in section 3, subject to your right to request deletion under section 13.

11.  HOW LONG WE KEEP YOUR INFORMATION

We keep personal information only for as long as it is needed for the purpose for which it was collected, or as required by law. The retention periods in section 3 apply as a general guide. When information is no longer needed, we delete or de-identify it securely.

  • Financial records including membership fee and event ticket transaction records are retained for 7 years in accordance with ATO requirements.
  • Member profile data is deleted within 30 days of membership ending.
  • Contact details are retained for up to 2 years after membership ends for legal and dispute resolution purposes, then deleted or de-identified.
  • If we cease to operate, all remaining member data will be deleted within 30 days of platform closure.

When your membership ends, Business Heads notifies Rewards Gateway, who will retain your data for 60 days before deletion, with order history retained for 2 years. Data held within Circle’s platform is subject to Circle’s own retention practices following deletion by Business Heads.

12.  PROTECTING YOUR INFORMATION

1.  Security measures

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Our measures include:

  • secure HTTPS connections on our website and member platform;
  • encryption of personal data at rest;
  • access controls and two-factor authentication for administrative accounts;
  • staff access to personal information limited on a need-to-know basis;
  • use of reputable third-party providers, including Rewards Gateway which holds ISO 27001 certification; and
  • a documented data breach response plan.

No system is completely secure. If you have concerns about the security of your information, please contact us at hello@businessheads.com.au.

2.  Data breaches

If we become aware of a data breach likely to result in serious harm, we will assess it promptly and, where required under the Notifiable Data Breaches scheme, notify affected individuals and the Office of the Australian Information Commissioner (OAIC).

13.  ACCESSING, CORRECTING AND DELETING YOUR INFORMATION

You have the right to request access to the personal information we hold about you, to ask us to correct inaccurate or incomplete information, and to request deletion of information that is no longer required. Contact us at hello@businessheads.com.au. We will respond within 30 days. Members can update most profile information directly through the member platform at any time.

1.  Deletion requests

Where you request deletion of your personal information, we will delete or de-identify information that we are not required to retain. Please note:

  • financial transaction records must be retained for 7 years in accordance with ATO requirements and cannot be deleted on request;
  • where your information is held within Circle’s platform, we will request deletion on your behalf and remove your access. Circle processes deletion requests and purges backup data in accordance with its own Data Processing Agreement;
  • Rewards Gateway retains order history for 2 years from the date of order and payment records for 1 year, subject to Rewards Gateway’s own retention obligations;
  • information you have shared directly with other members through the platform or through member deals referrals cannot be recalled from those individuals; and
  • information held by other third-party providers including Stripe is subject to those providers’ own retention policies.

We will confirm the outcome of your deletion request in writing within 30 days.

14.  THIRD PARTY LINKS

Our website, member platform and newsletters may contain links to external websites, LinkedIn profiles, member business websites and other third-party content. Business Heads is not responsible for the content or privacy practices of linked third-party sites. We encourage you to review the privacy policies of any external sites you visit.

15.  PRIVACY COMPLAINTS

If you have a concern about how we have handled your personal information, contact us at hello@businessheads.com.au. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

16.  CHANGES TO THIS POLICY

We may update this policy from time to time to reflect changes in our practices or in the law. We will notify current members of any material changes by email and by publishing the updated policy on our website with at least 30 days notice. The version number and effective date at the top of this policy will be updated with each revision. We review this policy at least annually.

17.  CONTACT US

For any privacy-related questions, requests or complaints:

Business nameBusiness Heads Pty Ltd
ABN78 693 566 326
Privacy contacthello@businessheads.com.au
Websitewww.businessheads.com.au
External regulatorOffice of the Australian Information Commissioner | www.oaic.gov.au | 1300 363 992